Our Confluence server was flagged by Qualys scan for the 11827 vulnerability.
The following headers are not present:
Header set X-Content-Type-Options: "nosniff"
Header set X-XSS-Protection: "1; mode=block"
Header set X-Frame-Options: "sameorigin"
As we are using the default Confluence installation which is using Apache Tomcat (built in or something),
how do I add these headers to the default config?